vendor:
MX-AOPC UA SERVER
by:
John Page AKA HYP3RLINX
5
CVSS
MEDIUM
XML External Entity Injection
611
CWE
Product Name: MX-AOPC UA SERVER
Affected Version From: 1.5
Affected Version To: 1.5
Patch Exists: YES
Related CWE: CVE-2017-7457
CPE: a:moxa:mx-aopc_ua_server:1.5
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux, Mac
2017
MOXA-MX-AOPC-SERVER-v1.5-XML-EXTERNAL-ENTITY
XML External Entity via '.AOP' files used by MX-AOPC Server result in remote file disclosure. If local user opens a specially crafted malicious MX-AOPC Server file type.
Mitigation:
Upgrade to MX-AOPC UA Server version 1.6 or later.